Request a device + user code (RFC 8628 §3.2)
Initiates a device-authorization grant. The CLI calls this first and receives a short user_code to display plus an opaque device_code to poll /api/auth/cli/token with (issue #165). Accepts both application/x-www-form-urlencoded (RFC 8628 §3.2, preferred) and application/json — the server normalizes form-urlencoded bodies to JSON before Better Auth's deviceAuthorization() plugin sees them. Clients are gated by validateClient — only OAuth clients registered with the device-code grant are accepted.
curl -X POST "https://your-instance/api/auth/device/code" \ -H "Content-Type: application/json" \ -d '{ "client_id": "string" }'{
"device_code": "string",
"user_code": "string",
"verification_uri": "http://example.com",
"verification_uri_complete": "http://example.com",
"expires_in": 0,
"interval": 0
}{
"error": "invalid_client",
"error_description": "string"
}